Trust and governance

Outsourcing should not mean losing control. Before work begins we define who decides, who approves, who has access, how information is protected, how issues escalate, and how the relationship exits cleanly.

Governance and accountability

Clear lines, named people

The two most common outsourcing failures are work requested informally that nobody has costed, and problems that escalate too late to fix. Both are prevented by knowing who talks to whom.

Named roles on both sides

Each party appoints an Executive Sponsor and Engagement Manager. We deliver through a Service Delivery Lead; you route instructions and escalation through your Engagement Owner.

A governance rhythm

Service reviews, monthly business reviews and quarterly steering meetings — sized to the engagement.

A decision trail

A maintained log of issues, risks, actions and decisions, so what was agreed and why is determinable afterwards rather than debatable.

Information security and privacy

Controls that travel with your data

We comply with the Data Privacy Act of 2012, its implementing rules and applicable National Privacy Commission issuances. For personal data processed on your instructions you are the Personal Information Controller and we are the Personal Information Processor.

Role-based access

Granted by role, reviewed on a cycle.

Least privilege

The minimum access the work requires, and no more.

Segregation of duties

Preparation, review and approval held by different people.

Documented approvals

Material actions carry a recorded, traceable authorisation.

Confidentiality

Survives termination — indefinitely for trade secrets and personal data.

Exception reporting

Material exceptions, suspected fraud and security incidents are escalated.

Data-subject support

Access requests, impact assessments and breach response supported.

Clean exit

Data returned or deleted on exit, subject to legal retention.

No system can be guaranteed completely secure or continuously available. Any provider who tells you otherwise is selling something. We commit to risk-based controls, prompt cooperation on incidents and honest reporting when something goes wrong. You should maintain backups, insurance and continuity measures appropriate to your own risk. For information collected through this website, see our privacy notice.
Service boundaries

Where our work ends

Our corporate purpose covers business support, management consulting and operational assistance. It excludes activities constituting the practice of professions regulated by the PRC, the IBP or other regulatory bodies — a working boundary, not a footnote.

The standard boundary, applied to every engagement

ProsInMotion performs

  • Administrative, operational and processing work
  • Preparation, coordination and documentation
  • Compliance tracking, filing support and reporting
  • Service management against agreed levels

You retain

  • Governance, management and business decisions
  • Accounting policies, estimates and tax positions
  • Approval of filings and external representations
  • Control of funds, seals and government credentials

A licensed professional is required for

  • Statutory audit and any assurance opinion
  • Legal advice, opinions and representation as counsel
  • Tax opinions and contested assessments
  • Notarisation and regulated certifications

Where a licensed professional is required, that person is engaged separately, by you, under their own engagement and their own fee. We identify the need and coordinate — we do not perform the work and do not invoice for it.

The same discipline applies to outcomes. We do not guarantee sales, leads, search ranking, vendor performance, savings, permits, approvals, legal outcomes or the absence of penalties. We commit to the work, done properly — not to results outside our control.
How our people are engaged

A genuine managed service, not labour supply

  • Our personnel remain our employees, contractors or authorised representatives — not yours
  • We exercise employer prerogatives: supervision, work allocation, performance, leave, discipline and substitution
  • We carry the wages, statutory benefits, contributions and employment records
  • You specify outcomes, policies, priorities, controls and acceptance criteria
  • Service concerns are raised with our designated manager, not with the individual

Engagements are built around outputs, methods and service levels — not the recruitment or supply of workers. DOLE Department Circular No. 01-17 recognises that genuine business-process and back-office outsourcing is not contemplated by Department Order No. 174 where an entire or specific business process is involved.

If the actual structure or deployment ever brings part of a service within contracting rules, both parties cooperate to comply. We would rather address that openly than pretend it cannot happen.
Continuity and exit

You should be able to leave

An engagement that cannot be unwound cleanly is a trap, not a service. Knowledge transfer, data return and exit planning are built in from the start.

  • An agreed exit plan with knowledge transfer
  • Return or transfer of your data and property
  • Access revoked and records preserved as legally required
  • Notice periods and any transition charges stated before you sign
Ethical standards

Lines we will not cross

Both parties comply with applicable anti-bribery, anti-fraud, sanctions and anti-money-laundering requirements. We may refuse or stop an instruction that appears unlawful, misleading, unethical or unsafe.

  • Falsifying records, bypassing controls or concealing incidents
  • Backdating documents
  • Improper payments, kickbacks or undisclosed commissions
  • Submitting anything inaccurate, misleading or inconsistent with official records

We may serve competitors, provided confidentiality is protected and conflicts managed. No exclusivity exists unless stated in a Service Order.

Design references

Frameworks we design against

ISO 9001:2015

Quality management

ISO/IEC 27001:2022

Information security

ISO 22301:2019

Business continuity

ISO 37301:2021

Compliance management

ISO 10002:2018

Complaints handling

ITIL 4 · COBIT · COSO

Service management, IT governance, internal control

These are design references, not certifications. Referencing a framework is guidance only — it does not represent certification, attestation or guaranteed conformity unless separately agreed and independently verified.
Where the legal detail lives. Warranties, liability, remedies, intellectual property and risk allocation are governed by the executed Engagement Letter and Service Order — not by this page. Your legal and finance teams are welcome to review the full terms, appendices and data-processing schedule at the scoping stage. We would rather you read them early than discover them late.

Questions about how we would handle your data or your risk?

Ask them before you sign, not after. We are happy to walk your legal, compliance or IT team through the control environment and the data-processing schedule in detail.